Four plans. Every limit here is the limit the software enforces.

The numbers below are read from the same constants the API checks against, and each row cites the file that enforces it. If a cap is not listed, it does not exist.

Micro

 

£29/mo

One person, one or two servers. Monitoring and the live activity feed, without the compliance register.

1 seat · 500 events/day

Create an account on the Micro plan

Starter

 

£99/mo

A small team that needs alerts and a shared workspace, and is starting to be asked compliance questions.

5 seats · 5,000 events/day

Create an account on the Starter plan

Business

Produces the register

£349/mo

The plan that produces the control register and the evidence export. This is the one to pick if an assessor is involved.

20 seats · 25,000 events/day

Create an account on the Business plan

Pro

 

£899/mo

Higher ingest, SOC 2 alongside the other frameworks, and custom detection rules.

9,999 seats · 100,000 events/day

Create an account on the Pro plan

What each plan enforces

Every row cites where it is enforced, so you can check it against the product rather than take it on trust.

Fortoxa plan comparison across Micro, Starter, Business and Pro
CapabilityMicroStarterBusinessPro
Enforced limitsThese are hard caps in the software, not fair-use guidance.
Seatsteam.ts:106,20115209,999
Log events per dayingest-events.ts:395005,00025,000100,000
Log events per billing periodusage.ts15,000150,000750,0003,000,000
Threats visible at oncethreats.ts:3531250100
Rows in the activity feeddashboard.ts:102341010
Framework coverageWhich registers the compliance service will build for your region.
Cyber Essentials · NCSC CAF (UK)compliance.ts:212Cyber Essentials · NCSC CAF (UK): not included in MicroCyber Essentials · NCSC CAF (UK): not included in StarterCyber Essentials · NCSC CAF (UK): included in BusinessCyber Essentials · NCSC CAF (UK): included in Pro
GDPR Article 32 · NIS2 (EU)compliance.ts:212GDPR Article 32 · NIS2 (EU): not included in MicroGDPR Article 32 · NIS2 (EU): not included in StarterGDPR Article 32 · NIS2 (EU): included in BusinessGDPR Article 32 · NIS2 (EU): included in Pro
SOC 2compliance.ts:267SOC 2: not included in MicroSOC 2: not included in StarterSOC 2: not included in BusinessSOC 2: included in Pro
Sections you can openGated in the app shell. Lower tiers see these listed and are sent to billing.
Overview, Incident Center, Investigations, Response ActionsSidebar.tsxOverview, Incident Center, Investigations, Response Actions: included in MicroOverview, Incident Center, Investigations, Response Actions: included in StarterOverview, Incident Center, Investigations, Response Actions: included in BusinessOverview, Incident Center, Investigations, Response Actions: included in Pro
Assets · Controls · Playbooks · Security MapSidebar.tsxAssets · Controls · Playbooks · Security Map: not included in MicroAssets · Controls · Playbooks · Security Map: not included in StarterAssets · Controls · Playbooks · Security Map: included in BusinessAssets · Controls · Playbooks · Security Map: included in Pro
Evidence Center · Audit ReadinessSidebar.tsxEvidence Center · Audit Readiness: not included in MicroEvidence Center · Audit Readiness: not included in StarterEvidence Center · Audit Readiness: included in BusinessEvidence Center · Audit Readiness: included in Pro
API keysSidebar.tsxAPI keys: not included in MicroAPI keys: not included in StarterAPI keys: included in BusinessAPI keys: included in Pro
Plan featuresFrom app/lib/tiers.ts, which drives the in-app upgrade prompts.
Real-time alertstiers.tsReal-time alerts: not included in MicroReal-time alerts: included in StarterReal-time alerts: included in BusinessReal-time alerts: included in Pro
Team managementtiers.tsTeam management: not included in MicroTeam management: included in StarterTeam management: included in BusinessTeam management: included in Pro
Alert rulestiers.tsAlert rules: not included in MicroAlert rules: not included in StarterAlert rules: included in BusinessAlert rules: included in Pro
Custom detection rulestiers.tsCustom detection rules: not included in MicroCustom detection rules: not included in StarterCustom detection rules: not included in BusinessCustom detection rules: included in Pro
Multi-workspacetiers.tsMulti-workspace: not included in MicroMulti-workspace: not included in StarterMulti-workspace: included in BusinessMulti-workspace: included in Pro
White-labeltiers.tsWhite-label: not included in MicroWhite-label: not included in StarterWhite-label: not included in BusinessWhite-label: included in Pro
Email supporttiers.tsEmail support: not included in MicroEmail support: included in StarterEmail support: included in BusinessEmail support: included in Pro
Priority supporttiers.tsPriority support: not included in MicroPriority support: not included in StarterPriority support: included in BusinessPriority support: included in Pro
Named account managertiers.tsNamed account manager: not included in MicroNamed account manager: not included in StarterNamed account manager: not included in BusinessNamed account manager: included in Pro
14-day trial on a new subscriptioncheckout.ts:5414-day trial on a new subscription: not included in Micro14-day trial on a new subscription: included in Starter14-day trial on a new subscription: included in Business14-day trial on a new subscription: not included in Pro

Two things this table does not claim

There is no data-retention tier. The previous version of this page listed 7, 30 and 90 days and one year; no retention logic exists in the product, so the rows were removed rather than reworded. There is also no service level agreement — if you need one, it has to be agreed, not read off a pricing page.